REvil/Sodinokibi continued to evolve its ransomware toolkit with updated encryption and execution features aimed at improving impact on victim environments. Analysis of version 2.2 showed the malware restored persistence through the Windows Run registry key when configured to do so and added use of the Windows Restart Manager to identify processes and services locking targeted files, then terminate those processes or stop and delete services so encryption can proceed. Researchers also noted the malware can remove a critical-process protection flag before killing a process, potentially destabilizing infected systems, while retaining familiar behaviors such as shadow copy deletion, process termination, ransom note deployment, wallpaper changes, and encrypted configuration parsing.
Separate reporting tied REvil to a broader set of delivery and targeting methods across Windows, Linux, and enterprise infrastructure. A PowerShell-based loader was observed disabling AMSI, decrypting an embedded payload, and using in-memory shellcode injection to launch REvil without writing the final executable directly to disk. Earlier technical analysis described phishing-delivered JavaScript loaders, PowerShell staging, UAC bypass, optional exploitation of CVE-2018-8453, and process hollowing, while additional reporting and indicators linked the group to Linux ransomware samples and exploitation of Oracle WebLogic Server vulnerabilities for initial access. Together, the references show an operation refining both its post-compromise encryption logic and its initial access and execution tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
An AlienVault OTX pulse for a Linux version of REvil was created and modified on June 28, 2021. The pulse published indicators for the Linux variant, including a YARA rule named REvilLinux and multiple ELF hashes.
SANS ISC analyzed a malicious PowerShell sample that used RunSpaces, an AMSI bypass, and shellcode-based loading to deploy REvil/Sodinokibi ransomware. The researcher concluded the actors' delivery method had shifted to a PowerShell RunSpace and shellcode-based loader.
Intel 471 states that REvil ransomware version 2.1 was first collected on March 15, 2020. The same source notes version 2.1 had removed the Run registry key persistence mechanism.
Cisco Talos published reporting on Sodinokibi ransomware exploiting a WebLogic Server vulnerability. This marks an early public report tying the ransomware to WebLogic-based intrusion activity.
A Panda Security report states that Sodinokibi, also known as REvil, first appeared in attacks on April 26, 2019. The report describes it as a ransomware-as-a-service operation.
Intel 471 analyzed REvil ransomware version 2.2 and reported that it restored Run-key persistence removed in version 2.1. The update also added Windows Restart Manager-based process and service termination and a new -silent command-line option.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourceotx.alienvault.com
Open sourceisc.sans.edu
Open sourceblog.talosintelligence.com
Open sourcecrowdstrike.com
Open sourcepandasecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.